← All stories
● Covered by 3 sources · 3 reportsMedium impact2 negative

MonsterCloud CEO Charged for Allegedly Defrauding Ransomware Victims with Secret Payments

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Zohar Pinhasi, CEO of MonsterCloud, faces wire fraud charges.
  • Pinhasi allegedly paid ransoms to attackers for decryption keys.
  • MonsterCloud falsely claimed to use proprietary data recovery tools.
  • Clients were charged significantly more than the actual ransom payments.
  • The alleged scheme ran from June 2018 to June 2023.

Ransomware Recovery CEO Indicted

Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," the owner and operator of MonsterCloud LLC, a Florida-based ransomware remediation company, has been indicted by a federal grand jury in the Eastern District of New York. He faces one count of conspiracy to commit wire fraud and two counts of wire fraud.

Pinhasi surrendered on Wednesday, pleaded not guilty, and was released on a $2 million bond. If convicted, he faces up to 20 years in prison for each count.

Allegations of Deception

Prosecutors allege that from June 2018 to June 2023, Pinhasi defrauded ransomware victims by secretly paying their attackers for decryption keys. MonsterCloud advertised that it possessed proprietary tools and advanced decryption techniques to recover encrypted data without paying cybercriminals.

According to the indictment, Pinhasi and his co-conspirators did not have such proprietary technology. Instead, they contacted ransomware operators, paid them for decryption keys, and then charged the victim organizations a fee for data restoration.

Significant Markups on Payments

The U.S. Attorney's Office states that Pinhasi's company charged clients significantly more than the ransom payments made. In one documented instance, Pinhasi allegedly made a ransom payment of approximately $8,200 to a ransomware affiliate but then charged the client approximately $150,000.

Throughout the alleged scheme, Pinhasi reportedly paid over $8 million in ransoms while billing his clients over $19 million.

Impact on Victims

U.S. Attorney Joseph Nocella, Jr. for the Eastern District of New York stated that by falsely claiming to decrypt ransomware without paying ransomers, Pinhasi "re-victimized his clients while extracting a hefty profit for himself." MonsterCloud's website claimed to use "advanced decryption techniques and cutting-edge technology" to restore data, urging victims not to pay ransoms.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Zohar Pinhasi, owner of MonsterCloud, was charged with wire fraud for allegedly deceiving ransomware victims. Pinhasi claimed to use proprietary tools for data recovery but instead paid ransoms to attackers, then charged clients significantly marked-up fees.

Zohar Pinhasi, CEO of MonsterCloud, faces charges for allegedly defrauding ransomware victims by secretly paying attackers for decryption keys while claiming to use proprietary technology. Prosecutors state Pinhasi's company charged clients significantly more than the ransom payments, despite contracts implying ransom payments were a last resort.